Offensive Security Researcher
Posted 2 days ago · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
This role involves conducting advanced offensive security research to identify and exploit vulnerabilities across applications, APIs, cloud environments, and infrastructure. You will develop novel attack techniques, proof-of-concept exploits, and automated tools to help build autonomous agentic pentesting capabilities. Day to day, you will collaborate with cross-functional teams to simulate realistic attack scenarios and ship offensive security capabilities into production.
- 4+ years of experience in offensive security, penetration testing, red teaming, application security, or vulnerability research
- Hands-on experience identifying and exploiting vulnerabilities in modern applications and infrastructure
- Deep understanding of web application security, APIs, authentication, authorization, and modern exploitation techniques
- Strong knowledge of OWASP Top 10
- Experience with vulnerability chaining and identifying complex attack paths
- Experience with cloud environments, Kubernetes, or modern infrastructure exploitation
- Experience with LLMs, AI agents, or autonomous systems
- Experience with exploit development
Extracted from the job description · kept up to date automatically
Who this suits
This role suits experienced security professionals with 4+ years in offensive security, penetration testing, red teaming, or vulnerability research who possess strong programming skills and an attacker mindset. It is less ideal for candidates seeking a traditional manual pentesting position without tool-building or automation responsibilities.
Full job description
Original listing · kept for referenceOX Security is securing the AI-driven SDLC from prompt to production. We’re building the next generation of security technology for a world where AI is changing how software is built, deployed, and attacked.
We’re looking for an experienced Offensive Security Researcher to join our Security Research group and help us rethink how offensive security can be performed at scale.
This is not a traditional pentesting role.
You’ll go beyond finding vulnerabilities. You’ll research how real-world attackers think and operate, discover ways to chain vulnerabilities and misconfigurations, develop novel attack techniques, and help build automated agentic systems that can continuously simulate attacks against modern applications and infrastructure.
You’ll work at the intersection of offensive security, application security, exploit development, automation, and AI - building the next generation of autonomous and agentic pentesting capabilities.
If you enjoy breaking complex systems, finding unexpected attack paths, and building tools that can do it repeatedly and at scale, this is the role for you.
Responsibilities:
What You'll Be Doing
• Conduct advanced offensive security research across modern applications, APIs, cloud environments, and infrastructure
• Identify and exploit vulnerabilities, misconfigurations, logic flaws, and weaknesses across complex systems
• Research and develop novel attack techniques and exploitation methods
• Discover and demonstrate multi-step attack chains and real-world attack paths
• Develop proof-of-concepts, exploits, and automated offensive security tools
• Build automated attack capabilities that can discover and validate exploitable vulnerabilities at scale
• Research how attackers can move from individual vulnerabilities to meaningful business impact
• Work with application, code, cloud, and runtime context to simulate realistic attack scenarios
• Prototype and ship offensive security & agentic capabilities into production
• Collaborate closely with Engineering, Product, AI, and Data teams to build next-generation security capabilities
• Contribute to the development of OX's autonomous and agentic pentesting technology
• Stay current with emerging exploitation techniques, offensive tooling, and real-world attack trends
Requirements:
What We're Looking For
• 4+ years of experience in offensive security, penetration testing, red teaming, application security, or vulnerability research
• Strong hands-on experience identifying and exploiting vulnerabilities in modern applications and infrastructure
• Deep understanding of web application security, APIs, authentication, authorization, and common attack techniques
• Strong knowledge of OWASP Top 10 and modern exploitation techniques
• Experience with vulnerability chaining and identifying complex attack paths
• Strong programming and scripting skills, with the ability to build offensive security tools and proof-of-concepts
• Ability to understand code and modern software architectures from an attacker's perspective
• Strong understanding of how modern applications and cloud environments can be attacked
• Ability to independently investigate complex systems and find creative ways to break them
• Strong communication skills and the ability to explain technical findings clearly
• A hands-on, curious, and highly technical mindset
The DNA We're Looking For
• Attacker mindset: You naturally think about how a system can be abused, bypassed, or broken
• Builder-breaker: You enjoy both finding vulnerabilities and building the tools to exploit and automate them
• Creative attacker: You look beyond known vulnerabilities and find unconventional attack paths
• Scale-oriented: You’re excited by the idea of turning a manual offensive technique into an automated, agentic capability
• Systems thinker: You understand how seemingly small weaknesses can combine into a real attack
• Fearless investigator: You enjoy complex, ambiguous problems where there is no obvious answer
• Ownership-driven: You take initiative, experiment quickly, and push ideas from research to production
Bonus Points For
• Experience with red teaming or advanced penetration testing
• Experience with exploit development
• Experience with bug bounty programs
• Experience with CTFs or competitive security research
• Experience with offensive security tooling and automation
• Experience attacking cloud environments, Kubernetes, or modern infrastructure
• Experience with LLMs, AI agents, or autonomous systems
• Experience researching real-world attack techniques or publishing technical research and CVEs
• Strong software engineering background
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- 4+ years of experience in offensive security, penetration testing, red teaming, application security, or vulnerability research, Hands-on experience identifying and exploiting vulnerabilities in modern applications and infrastructure, Deep understanding of web application security, APIs, authentication, authorization, and modern exploitation techniques, Strong knowledge of OWASP Top 10, Experience with vulnerability chaining and identifying complex attack paths